Quiropráctica La Zenia, go to homeLA ZENIA

Legal information

Privacy policy

Last updated: 25 August 2026

This page describes how we handle the personal data of people who book an appointment, get in touch through the contact form, or browse this site.

Reviewed by legal counsel: incorporates their written instructions of 13 and 18 August 2026, their reply of 21 August 2026 — which closes the seventeen points raised — and their reply of 22 August 2026 on verbal consent over the telephone and the retention period for access logs. No section remains pending review.

Data controller

Randall Morgan Jones Hey, Spanish tax ID (NIF) 48617850J, chartered physiotherapist, member no. 10369 (Colegio de Fisioterapeutas de la Comunidad Valenciana), registered as a self-employed professional under IAE heading 836 (physiotherapists), with a place of business at Calle San Antonio 1, bajo 6, 03189 Orihuela (Alicante), Spain.

Contact for privacy questions: quirodoc@quiropracticalazenia.com. Data-protection requests sent to that address are handled as a priority.

Purpose of processing

Managing appointment bookings and contacting you about your appointment (confirmation, reminder, cancellation). This site does not take or process payments: the price of the service is paid at the clinic on the day of your visit.

Replying to messages sent through the contact form.

Managing access to the online diary, including keeping a record of appointments that are neither attended nor cancelled at least 24 hours in advance, under the attendance commitment set out in the legal notice.

If you voluntarily state the reason for your visit, that data is treated as health data, under a specific consent separate from the rest. It is stored encrypted in the database and copied, together with your name, phone number and email, inside the appointment's event in the doctor's professional diary (Google Calendar), so the consultation can be prepared. It is not sent by email and is not disclosed to any other recipient.

Legal basis

Performance of the contractual relationship arising from the appointment booking (GDPR art. 6.1.b).

Your explicit consent for the health data given as the reason for the visit and, where applicable, for sending communications (GDPR art. 6.1.a and art. 9.2.a).

For appointments arranged by telephone, the reason for the consultation is recorded solely under the patient's explicit verbal consent. The system audits the date, the time and the authorised user who made the entry, linking that action to the verbal information protocol provided during the call (GDPR arts. 6.1.a and 9.2.a).

Legitimate interest in the administrative and accounting management of the professional activity and in the sound use of the online diary, preventing booked-but-unattended slots from denying access to other patients (GDPR art. 6.1.f).

Recipients and data processors

To provide the service we use the following technology providers, acting as data processors: Supabase (appointments database, hosted in the European Union), Vercel (website hosting and cookieless visitor statistics), Zoho (transactional email, European servers), and Google (the doctor's professional diary: as well as being checked to work out availability, it receives each appointment's details — name, phone number, email and the reason for the visit, if you gave one — inside the corresponding event).

No payment gateway is used, because this site does not process payments.

Some of these providers are companies established outside the European Economic Area. International transfers of data are carried out under the appropriate safeguards laid down in Chapter V of the General Data Protection Regulation (GDPR), principally by entering into Standard Contractual Clauses (SCC) approved by the European Commission, which guarantee a level of protection equivalent to the European one. The providers involved are Supabase, Vercel, Zoho and Google. In Google's case, because health data is involved, supplementary measures have been adopted to safeguard the transferred data.

Retention period

Clinical records: your appointment data and the reason for your visit, where you choose to give it, are kept for a minimum of five years from the date of the last treatment, under article 17 of Spanish Law 41/2002 on patient autonomy, to ensure continuity of care and for professional liability purposes.

Invoicing: data that forms part of an invoice is kept for six years under Spanish commercial and tax law (article 30 of the Commercial Code). Invoices are issued at the clinic, not through this website.

Contact-form messages that do not lead to an appointment or to a professional relationship are kept for a maximum of six months.

Each appointment is stored as an independent record, which allows these periods to be applied appointment by appointment and supports erasure requests covering data no longer subject to a statutory retention duty.

Access and security logs: these are kept for a period of 5 years to guarantee the traceability and auditing of access to health data, in compliance with the security obligations of the GDPR and applicable healthcare legislation.

Data subject rights

You can exercise your rights of access, rectification, erasure, objection, restriction of processing, and portability by writing to quirodoc@quiropracticalazenia.com or by post to Calle San Antonio 1, bajo 6, 03189 Orihuela (Alicante), Spain.

The right to erasure is limited where the data form part of the clinical record: Spanish healthcare law requires it to be kept for a minimum of five years from the end of the episode of care (art. 17.1 of Law 41/2002), so within that period it is not destroyed. What does happen immediately is blocking: the data are identified and set aside, are no longer accessible and are not used for any purpose, other than being made available to the courts, the public prosecutor or the competent authorities (art. 32 of Organic Law 3/2018). Once the period has elapsed, they are destroyed. On request you will be told the status of each item of data and the date from which it can be destroyed.

You may also file a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es) if you believe the processing does not comply with the regulations.

Appointments for minors

When an appointment is booked for a minor patient, the minor's data is collected under the consent of the adult who books the appointment as legal guardian, who gives the corresponding consent on the minor's behalf.

Security

Reasonable technical and organisational measures are applied to protect data, including encryption of the optional health data (reason for visit) in the database and hosting that database with a provider operating data centres in the European Union. That encryption protects the data while it is stored here; the copy that travels into the event in the doctor's professional diary sits outside it, under Google's own security measures.